This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall blocking

Hello,

I have added a Network Definitions group called "Blocked Attackers" and added several IP addresses and IP subnets.
I added a firewall rule (on position 1) with the following settings:

Sources: Blocked Attackers
Services: Any
Destinations: Any
Action: Drop (also tried reject)

The rule is enabled but I still see the IP address appear on the SMTP proxy trying to authenticate.

Am I missing something here?



This thread was automatically locked due to age.
Parents
  • Hoi Cris,

    Read #2 in Rulz to understand why your block rule is ineffective.  You want a blackhole DNAT instead.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hoi Cris,

    Read #2 in Rulz to understand why your block rule is ineffective.  You want a blackhole DNAT instead.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data